test22221@2.2.7
Malicious code in test22221 (npm)
Analysis
Package test22221@2.2.7 contains no executable code — only a package.json with malicious lifecycle hooks. On npm install, both the preinstall and postinstall scripts execute a curl command to IP 54[.]37[.]234[.]136 that exfiltrates the installer's username, hostname, and current working directory to the path /voicemail, and also fetches a second-stage value from hxxp://54[.]37[.]234[.]136/x123. The output is discarded to /dev/null to hide the activity. The package has no repository, no license, and no functional code — its sole purpose is to collect system metadata from anyone who installs it.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 07:49 AM
- analyzed
- Jul 29, 2026, 07:49 AM
Related advisories
- test2221@2.2.3
- blots@2.1.0
- @apexfnd/apex@1.0.1
- n8n-nodes-quick-utils@1.0.0
- n8n-nodes-task-runner@1.0.0
- n8n-nodes-devops-utils@1.0.0
- time-format-kit@1.0.2
- string-formatter-pro@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.